BTLO — Cerulean — Walkthrough
By Owais Ali Khan
BTLO — Cerulean — Walkthrough
By Owais Ali Khan

QUESTION 1

SOLUTION
First, I reviewed the Magnet report provided with the lab. I navigated to Chrome Web History, where I searched for the keyword “mail”. This revealed the event where Jane clicked a malicious IT support email.



The report only showed limited information about this event, so I proceeded to analyze Jane’s Chrome browser history directly. The Chrome history file is raw data and not easily readable. To convert it into a human-readable format, I used the Hindsight tool.

Hindsight parsed the raw Chrome artifacts and generated a readable file named History-Owais.xlsx, which I then opened using Timeline Explorer. Within Timeline Explorer, I searched for the keywords “mail” and “support” in the relevant columns. This allowed me to identify the exact time when Jane received and interacted with the malicious email.


ANSWER 1

QUESTION 2:

SOLUTION:
After analyzing the browser traffic logs, I observed that Google Drive had the highest number of entries. The total traffic count associated with Google Drive was 108, making it the most frequently accessed service.

ANSWER 2

QUESTION 3:

SOLUTION:
To identify the ITM (Insider Threat Matrix) ID, I focused my investigation on Google Drive activity, as it accounted for the highest traffic volume. By reviewing multiple Google Drive entries, I was able to determine the relevant ITM identifier.


ANSWER 3

QUESTION 4:

SOLUTION:
I navigated to the User Accounts section in the report. There, I reviewed Jane’s account details and identified the required information from the account description.


ANSWER 4

QUESTION 5:

SOLUTION
Initially, I checked the Installed Programs section and identified the entry for Slack, including its entry date and time. However, to determine the exact installation timeline, I again used Timeline Explorer to analyze the previously generated History-Owais.xlsx file.
This allowed me to correlate Slack-related activity with browser timestamps for accurate installation context.


ANSWER 5

QUESTION 6:

SOLUTION:
To identify an unofficial URL as evidence, I opened History-Owais.xlsx in Timeline Explorer once more. I located a login-related URL, which served as supporting evidence for this question.

ANSWER 6

Question 7:

Solution:
I navigated to the Remote Desktop section of the report. There, I identified evidence of an RDP connection associated with Jane’s system.

Answer 7

QUESTION 8:

SOLUTION:
Following the hint provided in the lab, I navigated to the Windows Defender log path using File Explorer. I opened the relevant MPLog_201… file and searched for the keywords “Project” and “Cerulean”.

This search revealed the required information to answer the question.
Then I searched “Project and Cerulean” and I got the Answer.


ANSWER 8

LAB COMPLETED

메타데이터
- post_id
- 28e2c2f150ce
- slug
- btlo-cerulean-walkthrough-28e2c2f150ce
- url
- https://medium.com/@owaisalikhan081/btlo-cerulean-walkthrough-28e2c2f150ce
- canonical_url
- https://medium.com/@owaisalikhan081/btlo-cerulean-walkthrough-28e2c2f150ce
- author_url
- https://medium.com/@owaisalikhan081
- status
- ok
- fetched_at
- 2026-06-09 15:37:30